Sceawere

Vulnerability Detail

CVE-2026-61978UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated Broken Access Control in Secure Card Gateway

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
7h ago
Vendor
webhosting4ugr
Product
Secure Card Gateway for ePay Paycenter (Piraeus Bank)
Attack Type
CWE-862 Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Broken Access Control in Secure Card Gateway for ePay Paycenter (Piraeus Bank) <= 1.0.32 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-08-13T14:17:03.337Z",
  "pubdate": "2026-08-13T14:17:03.337Z",
  "executiveSummary": "An unauthenticated broken access control vulnerability has been identified in the Secure Card Gateway for ePay Paycenter (Piraeus Bank) affecting versions 1.0.32 and below. This security flaw allows unauthenticated remote attackers to bypass authorization mechanisms and interact with restricted endpoints, functions, or resources that should otherwise require valid authentication or specific privilege levels.\nThe primary impact of this vulnerability includes potential unauthorized data access, manipulation of payment gateway operations, and compromise of sensitive financial transaction flows managed by the affected application. Because the vulnerability can be exploited without prior authentication over network boundaries, it presents a high severity risk to organizational assets and payment infrastructure.\nExploitation requires network access to the vulnerable Secure Card Gateway deployment and does not necessitate valid user credentials or prior system access. Remediation requires applying vendor-supplied updates or patches that correct access control enforcement logic across the affected application components.",
  "technicalDetails": "The root cause of the vulnerability stems from improper implementation or complete omission of access control checks within the request handling logic of the Secure Card Gateway for ePay Paycenter (Piraeus Bank) <= 1.0.32. The application fails to validate whether incoming HTTP requests originating from unauthenticated users possess the necessary authorization to invoke specific backend functions, access sensitive resources, or interact with restricted API endpoints.\nFrom an attack flow perspective, an unauthenticated remote attacker interacts directly with the network-exposed Secure Card Gateway. By crafting and transmitting targeted HTTP requests directly to protected endpoints, the attacker bypasses the application layer security checks that normally govern authenticated sessions. Since the vulnerable component fails to validate session states, tokens, or user roles prior to executing core logic, the request is processed successfully.\nThe affected component involves the authorization middleware and routing controllers of the Secure Card Gateway. Due to the lack of strict access restriction policies, arbitrary external entities can leverage this flaw to trigger sensitive transaction-handling functions or retrieve restricted operational data. The network exposure is typically external, directly facing clients interacting with the payment gateway infrastructure.\nPost-exploitation impact depends on the specific functions exposed through the bypassed endpoints, potentially leading to unauthorized disclosure of sensitive transaction data, financial fraud vectors, or operational disruption of the ePay Paycenter integration. Mitigation requires enforcing rigorous authentication and authorization checks at every application entry point, ensuring that access control lists (ACLs) are correctly applied and validated prior to request processing."
}
CVE-2026-61978: Unauthenticated Broken Access Control in Secure Card Gateway (MEDIUM Severity, CVSS: 6.5) - Sceawere